Skip to main content

Configuration reference

The whole configuration lives in the file .env in the bundle folder. setup.sh creates it from .env.example, which documents every setting with comments. This page lists the settings in the same groups.

  • Set by setup.sh means that setup.sh fills the value: secrets are generated once when empty, and derived values are rewritten from the public URL and the TLS mode on every run. Do not edit derived values by hand; run setup.sh instead.
  • A setting shown as (commented out) is present in .env.example but inactive until you remove the #.

Apply changes with docker compose up -d.

Release​

SettingDefaultMeaning
GOAT_VERSIONthe bundle's releaseThe GOAT version all images use. See Upgrades.
GOAT_REGISTRYghcr.io/plan4better/goatWhere the GOAT images are pulled from, e.g. an internal mirror

Public address and TLS​

SettingDefaultMeaning
GOAT_PUBLIC_URLasked by setup.shThe URL users type into the browser, without a trailing slash
GOAT_TLSautoauto, custom, internal or off; see HTTPS and addresses
GOAT_ACME_EMAILemptyOptional contact for Let's Encrypt expiry notices (auto only)
GOAT_TRUSTED_PROXIESprivate_rangesAddresses allowed to set X-Forwarded-* headers (your load balancer), as CIDRs separated by spaces
GOAT_ADMIN_ALLOW_CIDRS0.0.0.0/0 ::/0Networks allowed to open the Keycloak admin console under /keycloak/admin
GOAT_CA_BUNDLEemptyPath inside the containers of an extra CA certificate (PEM) in ./certs; set by setup.sh in internal mode. See Company CA.
GOAT_HTTP_PORT80Port for HTTP; set by setup.sh from the URL or --http-port
GOAT_HTTPS_PORT443Port for HTTPS; set by setup.sh from the URL
GOAT_HOSTNAME, GOAT_NETWORK_ALIAS, GOAT_SITE_ADDRESS, GOAT_HTTPS_PUBLISH, GOAT_KEYCLOAK_SSL_REQUIREDDerived; set by setup.sh

Profiles​

SettingDefaultMeaning
COMPOSE_PROFILESgarage,keycloakThe bundled components to run: garage (object storage), keycloak (login server), backup (nightly backups)

Authentication​

SettingDefaultMeaning
AUTHTrueTrue: users log in through Keycloak. False: no login, everybody acts as one built-in administrator (local and demo installs only).
GOAT_ADMIN_EMAILasked by setup.shThe first GOAT user, created in the bundled Keycloak on the first start
GOAT_ADMIN_PASSWORDset by setup.shPassword of the first user
REALM_NAMEgoatKeycloak realm GOAT uses
KEYCLOAK_CLIENT_IDgoatKeycloak client GOAT uses
KEYCLOAK_CLIENT_SECRETset by setup.shSecret of that client
KEYCLOAK_ADMIN_PASSWORDset by setup.shPassword of the user admin in the Keycloak admin console
KEYCLOAK_PROVISION_INVITED_USERStrueCreate the login account in Keycloak when someone is invited whose email has none yet
KEYCLOAK_DB_PASSWORDset by setup.shDatabase password of the bundled Keycloak
KEYCLOAK_PUBLIC_URL, KEYCLOAK_INTERNAL_URL(commented out)Your own Keycloak; see Your own Keycloak

Object storage (S3)​

SettingDefaultMeaning
S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEYset by setup.shAccess key for the bundled Garage, or your own S3 key
GARAGE_RPC_SECRET, GARAGE_ADMIN_TOKENset by setup.shInternal secrets of the bundled Garage
S3_ENDPOINT_URL, S3_PUBLIC_ENDPOINT_URL, S3_REGION, S3_BUCKET_NAME, S3_FORCE_PATH_STYLE(commented out)Your own S3; see Your own S3 storage
ASSETS_S3_ENDPOINT_URL, ASSETS_BUCKET_NAME, ASSETS_URL(commented out)The publicly readable bucket for avatars and images on your own S3

Database​

The memory defaults suit a 16 GB machine. As a rule of thumb, set POSTGRES_SHARED_BUFFERS to about 1/4 and POSTGRES_EFFECTIVE_CACHE_SIZE to about 3/4 of the RAM you give PostgreSQL.

SettingDefaultMeaning
POSTGRES_PASSWORDset by setup.shPassword of the GOAT database
WINDMILL_DB_PASSWORDset by setup.shPassword of the Windmill database
POSTGRES_SHARED_BUFFERS1GBPostgreSQL shared_buffers
POSTGRES_EFFECTIVE_CACHE_SIZE3GBPostgreSQL effective_cache_size
POSTGRES_MAX_CONNECTIONS200PostgreSQL max_connections
POSTGRES_POOL_SIZE5Connection pool size of the Core API
POSTGRES_MAX_OVERFLOW10Extra connections the Core API may open beyond the pool

Jobs (Windmill)​

SettingDefaultMeaning
WINDMILL_ADMIN_PASSWORDset by setup.shPassword of admin@windmill.dev in the Windmill interface
GOAT_TOOLS_WORKERS2Number of analysis jobs that run in parallel; each tools worker may use up to 4 GB of RAM
WINDMILL_LOCAL_PORT8110Port of the Windmill interface, bound to 127.0.0.1 only; see Windmill
GOAT_BASE_DATA_URLhttps://goat-base-data.plan4better.de/Source of the routing and public transport base data; see Routing base data

Web app secrets​

SettingDefaultMeaning
NEXTAUTH_SECRETset by setup.shSigning key for the web app's login sessions

Optional integrations​

SettingDefaultMeaning
NEXT_PUBLIC_MAPTILER_KEYemptyMapTiler key for the satellite/hybrid basemap (hidden when empty)
NEXT_PUBLIC_MAPBOX_TOKENemptyMapbox token for the place search
CATALOG_S3_BUCKET, CATALOG_S3_ENDPOINT_URL, CATALOG_S3_ACCESS_KEY_ID, CATALOG_S3_SECRET_ACCESS_KEY, CATALOG_S3_REGIONemptyThe GOAT data catalog (read-only bucket with the harmonised datasets)
GEOCODING_URL, GEOCODING_AUTHORIZATIONemptyGeocoding service used by analysis tools
NEXT_PUBLIC_WEBSITE_URLhttps://www.plan4better.deWebsite link and feeds shown in the app
NEXT_PUBLIC_STATUS_FEED_URLemptyStatus feed shown in the app
NEXT_PUBLIC_DOCS_URLhttps://goat.plan4better.de/docsDocumentation link in the app
STATIC_ASSETS_URLhttps://assets.plan4better.deProduct artwork: icons, default thumbnails, email images
OTEL_ENABLEDfalseExport traces, metrics and logs through OpenTelemetry
OTEL_EXPORTER_OTLP_ENDPOINTemptyYour OpenTelemetry (OTLP) endpoint

Email​

See Email for how these work together.

SettingDefaultMeaning
SMTP_HOSTemptyMail server; email is off while empty
SMTP_PORT587Port of the mail server
SMTP_SECURITYstarttlsstarttls, ssl or none
SMTP_USER, SMTP_PASSWORDemptyLogin; leave both empty for a relay without login
SMTP_FROMemptySender address; SMTP_USER when empty
EMAILS_FROM_NAMEGOATSender name
SMTP_STARTTLS, SMTP_SSLtrue, falseDerived from SMTP_SECURITY; set by setup.sh
EMAIL_BRAND_NAME, EMAIL_LOGO_URL, EMAIL_CONTACT_URL, EMAIL_PRIVACY_URL(commented out)Optional branding: name, logo instead of the name, footer links

Backups​

These apply when the backup profile is on; see Backups.

SettingDefaultMeaning
BACKUP_TIME02:30Time of the nightly backup (UTC)
BACKUP_RETENTION_DAYS7Backups older than this many days are removed